Consent under Kenya’s Data Protection Act: a business guide
Last updated 30 July 2026
If your business verifies people, screens candidates or collects personal data in any way, consent is often the lawful basis you rely on — and getting it right matters. This guide explains what valid consent means under Kenya’s Data Protection Act, how to obtain and record it, and the common mistakes to avoid. It draws on the Act and the ODPC’s guidance on consent, and is general information, not legal advice.
What consent means under the Act
Kenya’s Data Protection Act sets a high bar for consent. It must be an express, unequivocal, free, specific and informed indication of the person’s wishes — given by a clear statement or a clear affirmative action. Silence, inactivity or a pre-ticked box is not consent.
The tests of valid consent
- Freely given — a genuine choice, with no penalty or disadvantage for saying no.
- Specific — tied to a clear, stated purpose, not bundled with unrelated ones.
- Informed — the person knows who you are, what data you collect, why, and their rights.
- Unambiguous — expressed by a positive act, so there is no doubt they agreed.
When consent is (and isn’t) the right basis
Consent is one of eight lawful bases the Act allows for processing personal data (section 30) — others include performing a contract or meeting a legal obligation. Consent is not always the best choice: if a person cannot realistically refuse, or agreeing is made a condition of a service they need, that consent may not be “freely given”. For verification and background checks, though, consent is usually the cleanest and most transparent basis.
Verify with confidence — start free
No subscription · pay per check · consent built in
How to obtain valid consent, step by step
- 1
Be transparent up front
Tell the person who you are, what personal data you will collect, the purpose, how long you will keep it, and their rights — before they agree.
- 2
Make it specific and granular
Ask for consent for each distinct purpose separately. Do not bundle unrelated processing into one blanket “I agree”.
- 3
Use a clear affirmative action
Have the person actively opt in — a ticked box, a signature, a tap to approve. Never rely on pre-ticked boxes, silence or inactivity.
- 4
Make refusal and withdrawal easy
Give a real option to say no, and make withdrawing consent later as easy as giving it.
- 5
Keep a record
Store what the person consented to and when. You bear the burden of proving consent, so the record is what protects you.
What a valid consent request must include
The ODPC guidance sets out the minimum a consent request should contain. It must be prominent, concise, separate from other terms and conditions, and in plain language — and cover:
- Your identity — the data controller/processor, plus any third party relying on the consent.
- The purposes — every purpose the consent is being sought for.
- The processing activities — granular options for each separate type of processing.
- The right to withdraw — and how the person can do it.
Consent must come first — and can’t “evolve”
A valid basis must be in place before processing starts, so consent is sought up front. And there is no such thing as “evolving” consent: if your purpose changes, you need fresh, specific consent (or a different lawful basis) — you can’t stretch old consent to cover a new use, or retrospectively switch to another basis if the consent turns out to be invalid.
Withdrawing consent
A person can withdraw consent at any time, and it should be as easy to withdraw as it was to give. Once they do, you must stop the processing that relied on that consent (withdrawal does not undo processing already lawfully done). Building an easy withdrawal path in from the start is far simpler than retrofitting it.
Children and sensitive data
Processing a child’s personal data generally requires the consent of a parent or guardian and must be in the child’s best interests. Sensitive personal data — such as health or biometric data — carries a higher bar. Treat both with extra care and confirm the specific requirements before you proceed.
How Verifisha handles consent
Verifisha is built consent-first: before any check runs, the person receives a clear consent request, and their approval is stored as audit-ready evidence — so your verification is both lawful and defensible. It supports your obligations; it does not replace your own data-protection program or legal counsel.
This guide is general information based on Kenya’s Data Protection Act, 2019 and the ODPC Guidance Notes on Consent — it is not legal advice. The Act, the ODPC guidance and their interpretation change over time; confirm current requirements with the Office of the Data Protection Commissioner (odpc.go.ke) or a qualified adviser before relying on this guide.
Verifying someone else?
Verifisha brings identity, business, CRB, AML and reference checks together — with consent built in — so you get the full picture in one place.
No subscription · pay per check · consent-led & ODPC-aligned
Or get verified yourself
It is not only for checking other people — verify your own identity and build a vetted, shareable trust profile you can send to employers, landlords or partners. Get verified once and reuse it everywhere, with consent.
Frequently asked questions
What is valid consent under Kenya’s Data Protection Act?
Consent that is express, unequivocal, free, specific and informed — given by a clear statement or affirmative action. Silence, inactivity or a pre-ticked box does not count.
Do I always need consent to process personal data?
No. Consent is one lawful basis; the Act recognises others, such as performing a contract or meeting a legal obligation. For verification and background checks, consent is usually the cleanest basis.
Can a person withdraw their consent?
Yes — at any time, and as easily as they gave it. Once withdrawn, you must stop the processing that relied on it.
Do I need to keep proof of consent?
Yes. The data controller bears the burden of proving consent was obtained, so keep a record of what the person agreed to and when. Verifisha stores each approval as evidence.
What about consent for children?
Processing a child’s data generally needs the consent of a parent or guardian and must be in the child’s best interests. Confirm the specific requirements before proceeding.
Verify anyone — or get verified yourself.
Run consent-led KYC, KYB, AML, CRB and background checks in one place — or build your own verified, shareable trust profile for jobs, rentals and deals. Trust made simple, for Kenya and Africa.